From pilots to firmwide impact: BPM builds a Copilot culture for high-stakes work | Microsoft Customer Stories
See how one firm keeps high-stakes work moving under busy-season pressure. This customer story shows how BPM, a US accounting and advisory firm, embeds Microsoft 365 Copilot into daily workflows and builds agents to support planning, quality checks, and decision-making, all with enterprise-grade security and governance. Read the story to learn from BPM's experience with Microsoft 365 Copilot.
Why did BPM standardize on Microsoft 365 Copilot instead of using multiple AI tools?
BPM needed AI that could scale across a growing firm without increasing risk or creating a patchwork of unmanaged tools. Over the past five years, the firm materially increased headcount and grew revenue by roughly 50%, which raised the bar on consistency, quality, and governance.
Instead of allowing ad hoc use of consumer AI tools, BPM chose to standardize on Microsoft 365 Copilot as its trusted, enterprise-grade platform because it:
- Embeds AI in the flow of work – directly in Word, Excel, Outlook, and Teams, so people don’t have to stop, switch tools, or relearn workflows.
- Aligns with existing security and governance – Copilot respects current roles and permissions, so people only see what they already have rights to access.
- Provides enterprise protections – data is not used for training, not retained, and is governed with identity and access controls that fit BPM’s Microsoft infrastructure.
- Supports firmwide licensing – everyone in the firm is licensed, giving colleagues a sanctioned AI experience instead of scattered, unmanaged tools.
Leaders also put an AI Acceptable Use Policy in place and required colleagues to read and acknowledge it. This combination of a single, secure platform plus clear guardrails allowed BPM to scale AI responsibly, without compromising on accuracy, trust, or compliance.
How is BPM using Copilot and AI agents in high-stakes tax and assurance work?
BPM uses Microsoft 365 Copilot and custom AI agents to help teams handle high-pressure, high-stakes work without lowering quality standards.
In busy season, Tax and Assurance teams face a compressed window where they must quickly rebuild client context—what happened last year, what changed, and what might affect filing positions. Copilot helps by:
- Summarizing client history and documents so teams can get oriented faster and reduce “startup friction.”
- Managing message overload by summarizing long email and Teams threads and surfacing what needs action.
- Refining communication – leaders report using Copilot “nine times out of ten” to fine-tune messaging, tone, and clarity before sending important emails.
For more complex needs, BPM uses AI agents that embed firm expertise directly into workflows:
- Tax planning agent – evaluates a tax return against BPM’s planning frameworks and surfaces potential opportunities earlier. This lets staff at earlier career stages take a first pass at planning and build analytical skills sooner.
- Quality checkpoint agent – applies clear criteria from subject matter experts to flag when work needs a second review from national tax or estate and trust specialists. This reduces guesswork and creates a documented record of due diligence.
Across the firm, leaders report that tasks that once took days or weeks can now be completed in a single day, while maintaining the same or higher quality. The goal is not to replace professional judgment, but to standardize the right questions, reduce friction, and free time for higher-value advisory work.
How did BPM ensure AI adoption was safe, responsible, and actually used by employees?
BPM treated Copilot as a change in how the firm works, not just another software rollout. The focus was on safe, responsible adoption at scale and on making AI genuinely useful in day-to-day work.
Key steps included:
- Firmwide licensing – BPM did not roll Copilot out in phases; they licensed everyone in the firm to avoid pockets of usage and shadow tools.
- Clear governance and policy – leaders created an AI Acceptable Use Policy, defined which AI tools were approved or restricted, and aligned Copilot with existing security, privacy, and governance requirements.
- Enterprise-grade security – with Microsoft, BPM ensured data is not used for training, not retained, and is protected by identity and access controls. Copilot respects existing roles and permissions, so users only see what they are already allowed to see.
- Role-based training and enablement – BPM partnered with Reply to deliver training tailored to specific roles and to show how Copilot fits into everyday workflows in Word, Excel, Outlook, and Teams.
- Ongoing governance program – IT treated Copilot as a firmwide governance initiative, putting guardrails, operating discipline, and adoption rhythms in place rather than a one-time deployment.
- Internal champions and practice leaders – with a relatively small IT team supporting about 1,300 people, BPM relied on practice leaders and internal champions to drive adoption and share practical use cases.
Leaders consistently reinforced that AI is there to remove friction, not replace judgment. For example, drafting policies and guidance that once took days to weeks now happens in a day, but the same review discipline and accountability for final work remain. This balance of enablement and control helped BPM reimagine how work gets done while maintaining trust, accuracy, and culture.

From pilots to firmwide impact: BPM builds a Copilot culture for high-stakes work | Microsoft Customer Stories
published by BlueTeamAssess LLC
I founded BlueTeamAssess LLC to develop and offer actionable and cost effective security solutions to SMBs.
BlueTeamAssess LLC is a veteran-owned Cybersecurity Consulting business based in Onslow County, NC.
My company wants to be the trusted advisor to small businesses for cybersecurity and related information technology needs. We will help you meet compliance requirements for HIPAA, PCI, NC cybersecurity requirements for financial advisors, and NIST 800-171 and CMMC cybersecurity requirements for providing goods and services through DOD contracts.
We help small businesses understand cybersecurity threats and their vulnerability to those threats. We offer affordable products and services to protect their business and their livelihood from those threats.
We use the SAINT Security Suite and its family of assessment products to provide cybersecurity services that assess your exposure to the many threats that can impact your business. And we help you meet compliance requirements for NIST 800-171 cybersecurity requirements for providing goods and services through DOD contracts as well as for HIPAA, PCI, the NC data breach protection law and NC cybersecurity requirements for financial advisors.
We use the CyberSecurity Assessment Tool from QS Solutions to assess the security posture of your Microsoft 365 deployment and help bring your risk score to acceptable levels through our remediation services.
We will help you reduce SPAM, secure your email and defend against ransomware. To help do this, we offer a number of solutions scalable for small business budgets and environments. These include:
- Microsoft 365 email and office software and its extensive security features and advanced threat protection.
- Fortinet security solutions that provide a Security Fabric that knits together protection for your endpoints and servers, your firewalls, your wireless network, security analytics and many other services that protect your organization technology from today’s advanced threats whether the workers are working in the office or remotely from home.
- A backup and recovery solution from Acronis to protect your critical customer and business data when the next storm or other disaster impacts your business.
You can trust BlueTeamAssess LLC be the trusted advisor to small businesses for cybersecurity and related information technology needs.